GitLab
cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*
- >= 17.10, < 18.9.7
- >= 18.10, < 18.10.6
- >= 18.11, < 18.11.3
An authorization vulnerability has been addressed in GitLab CE/EE versions 17.10 prior to 18.9.7, 18.10 prior to 18.10.6, and 18.11 prior to 18.11.3. This vulnerability could have permitted an authenticated user with developer-role permissions to delete protected container registry tags, due to inadequate authorization checks.
Exploitation of this vulnerability could lead to unauthorized deletion of protected container registry tags.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.